npm
13 stories on npm, newest first, from 13 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting.
- 101 Malicious npm Packages Hijack Developers' WhatsApp Accounts to Boost Fake Groups
- Malicious npm and PyPI Packages Deliver Credential-Stealing Malware to Developers
- Fake 'Twilio Bug Bounty' npm Package Caught Stealing Developer Credentials
- CrowdSec's GitHub Data Stolen in Shai-Hulud Supply Chain Attack
- Malicious npm Package Skips Install Scripts, Hides Malware in Application Code Instead
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- New 'WeaselBiscuit' Malware Found Hidden in 13 npm Packages Targeting Developers
- Fake 'Bug Bounty Hunter' Used AI-Written Malware to Raid npm Developer Secrets
- PhantomRaven: An AI-Written Info Stealer Hidden in npm Packages, Used to Hunt Bug Bounties
- Fake npm Packages Used to Host Phishing CAPTCHA Scams
- AI-Powered Backdoor Hidden in Fake npm Packages Targets Linux Systems
- Nearly 800 Fake npm Packages Caught Spreading Malware Across Windows, Mac and Linux
- Massive Supply Chain Attack Hits Over 400 NPM Software Packages